Malware abuses Google OAuth endpoint to ‘revive’ cookies, hijack accounts

Discussion in 'malware problems & news' started by stapp, Dec 29, 2023.

  1. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    27,172
    Location:
    UK
  2. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,222
    Location:
    Member state of European Union
    What? How this passed code review?
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    This just shows that Google is a joke when it comes to security. So if I understood correctly, if these infostealers manage to steal certain information included in cookies like account ID's and tokens, they can keep getting access to accounts, no matter if passwords are changed? And I guess this will even bypass hardware security keys, what a joke! :gack:
     
  4. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,597
    Location:
    Flat Earth Matrix
    And Google is forcing passkeys, which are even worse. Edge forced a passkey for MSA and now I am logged 24/7 without cookies, without 2FA, previously I got at least Windows Hello prompt and they call it an improved security?! o_O
     
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    LOL good point, I wouldn't be surprised if cookie stealing malware can even bypass passkeys.
     
  6. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Google is downplaying this threat (see quote), they say you can always sign out those unrecognized devices, which I guess is true. But wasn't the problem that hackers can keep creating cookies that allow them to sign in again and again? :confused:

    https://www.androidpolice.com/dangerous-malware-cookies-breaks-google-accounts/
     
  7. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,597
    Location:
    Flat Earth Matrix
    Indeed, but they currently have no solution, no workaround, so they pretend that everything is OK to avoid the panic. Not like people would panic, they do not even know, what cookies are, but media would go nuts.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.